detecting-directory-listing
Warn
Audited by Socket on Aug 21, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally coherent and does not show credential theft or deceptive third-party routing, but it gives an AI agent active penetration-testing capability against arbitrary hosts. Main concerns are offensive use, broad curl permission, and untrusted remote content handling rather than malware behavior.
Confidence: 91%Severity: 72%
Audit Metadata